EP3796107A1 - Système de guidage et procédé de gestion des certificats - Google Patents
Système de guidage et procédé de gestion des certificats Download PDFInfo
- Publication number
- EP3796107A1 EP3796107A1 EP19197796.6A EP19197796A EP3796107A1 EP 3796107 A1 EP3796107 A1 EP 3796107A1 EP 19197796 A EP19197796 A EP 19197796A EP 3796107 A1 EP3796107 A1 EP 3796107A1
- Authority
- EP
- European Patent Office
- Prior art keywords
- registration service
- component
- specific information
- central
- certification
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Withdrawn
Links
Images
Classifications
-
- G—PHYSICS
- G05—CONTROLLING; REGULATING
- G05B—CONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
- G05B9/00—Safety arrangements
- G05B9/02—Safety arrangements electric
-
- G—PHYSICS
- G05—CONTROLLING; REGULATING
- G05B—CONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
- G05B19/00—Program-control systems
- G05B19/02—Program-control systems electric
- G05B19/04—Program control other than numerical control, i.e. in sequence controllers or logic controllers
- G05B19/042—Program control other than numerical control, i.e. in sequence controllers or logic controllers using digital processors
- G05B19/0428—Safety, monitoring
-
- G—PHYSICS
- G05—CONTROLLING; REGULATING
- G05B—CONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
- G05B19/00—Program-control systems
- G05B19/02—Program-control systems electric
- G05B19/418—Total factory control, i.e. centrally controlling a plurality of machines, e.g. direct or distributed numerical control [DNC], flexible manufacturing systems [FMS], integrated manufacturing systems [IMS] or computer integrated manufacturing [CIM]
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/12—Applying verification of the received information
- H04L63/126—Applying verification of the received information the source of the received data
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L9/00—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols
- H04L9/32—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials
- H04L9/3263—Cryptographic mechanisms or cryptographic arrangements for secret or secure communications; Network security protocols including means for verifying the identity or authority of a user of the system or for message authentication, e.g. authorization, entity authentication, data integrity or data verification, non-repudiation, key authentication or verification of credentials involving certificates, e.g. public key certificate [PKC] or attribute certificate [AC]; Public key infrastructure [PKI] arrangements
-
- G—PHYSICS
- G05—CONTROLLING; REGULATING
- G05B—CONTROL OR REGULATING SYSTEMS IN GENERAL; FUNCTIONAL ELEMENTS OF SUCH SYSTEMS; MONITORING OR TESTING ARRANGEMENTS FOR SUCH SYSTEMS OR ELEMENTS
- G05B2219/00—Program-control systems
- G05B2219/30—Nc systems
- G05B2219/36—Nc in input of data, input key till input tape
- G05B2219/36542—Cryptography, encrypt, access, authorize with key, code, password
-
- Y—GENERAL TAGGING OF NEW TECHNOLOGICAL DEVELOPMENTS; GENERAL TAGGING OF CROSS-SECTIONAL TECHNOLOGIES SPANNING OVER SEVERAL SECTIONS OF THE IPC; TECHNICAL SUBJECTS COVERED BY FORMER USPC CROSS-REFERENCE ART COLLECTIONS [XRACs] AND DIGESTS
- Y02—TECHNOLOGIES OR APPLICATIONS FOR MITIGATION OR ADAPTATION AGAINST CLIMATE CHANGE
- Y02P—CLIMATE CHANGE MITIGATION TECHNOLOGIES IN THE PRODUCTION OR PROCESSING OF GOODS
- Y02P90/00—Enabling technologies with a potential contribution to greenhouse gas [GHG] emissions mitigation
- Y02P90/02—Total factory control, e.g. smart factories, flexible manufacturing systems [FMS] or integrated manufacturing systems [IMS]
Definitions
- the present invention relates to a control system for a process plant and a method for certificate management in a process plant.
- a system can be composed, for example, of a large number of components, possibly networked with one another and / or interdependent, such as valves, sensors, actuators and / or the like.
- (digital) certificates are usually used, which can be issued, distributed and checked within a corresponding control system.
- a control system can, for example, be based on what is known as a public key infrastructure (PKI).
- PKI public key infrastructure
- control systems of heterogeneous plants usually have central software inventories in which identity and authenticity-creating data on the components, e.g. B. device certificates in the form of manufacturer certificates (Manufacturer Device Certificates), serial numbers and / or the like are stored. This data is usually stored manually in the software inventory when the system is planned or initialized.
- a first aspect of the invention relates to a control system for a process plant, with a central registration service that is set up to check a certification application for a plant component on the basis of component-specific information, and a software inventory that is set up to store the component-specific information .
- the control system has at least one local registration service which is set up to transmit the certification application from the system component to the central registration service.
- the at least one local registration service is set up to send the component-specific information together with the certification application, in particular as part of the certification application to be transmitted to the central registration service.
- the central registration service is set up to manage the software inventory on the basis of the component-specific information transmitted by the local registration service.
- a certification application within the meaning of the invention is, in particular, a request from a, z. B. operational, certificate for a system component and is also referred to as Certificate Signing Request (CSR).
- CSR Certificate Signing Request
- Such a request can in particular contain at least one signature of the respective system component making the application, which can optionally be checked for validity by a registration service.
- the certificate can allow the system component, for example, to communicate securely, in particular encrypted, with other system components.
- a system component within the meaning of the invention is in particular a physical component or a component of the process engineering system implemented as software.
- a system component can, for example, be a device or an application that z. B. runs as software on a server in the system.
- a central software inventory within the meaning of the invention is in particular a digital catalog or a digital directory.
- the software inventory preferably at least some of the system components can be recorded together with the respective component-specific information. If necessary, certification paths called “trust chains” can also be stored in the software inventory, which represent a chain of certificates.
- the software inventory can in particular be designed as a database or a list.
- Management of a software inventory within the meaning of the invention is, in particular, maintenance of the software inventory.
- a modification of the software inventory can, for example, be carried out as part of the administration.
- Management of the software inventory preferably includes adding, Changing and / or deleting entries or data records in the inventory.
- One aspect of the invention is based on the approach of adding additional information regarding the applying system component to a certification application submitted by a system component, in particular when forwarding such an application from a local registration service to a central or cross-system registration service of a process engineering system.
- the component-specific information can in particular be transmitted to the central registration service as part of the forwarded certification application.
- the component-specific information is preferably at least partially information which enables the certification application to be checked by the central registration service, in particular which is necessary for checking.
- the component-specific information can include so-called meta information, which describes, for example, the role of the system component in its local system environment, for example within an autonomously functioning and secured system segment, or the networking of the system components with other system components.
- the central registration service is preferably set up to store the component-specific information in a particularly central or cross-system software inventory and thus make it available, for example, for further future checks of incoming certification applications or for a centrally initiated renewal of certificates .
- the software inventory of a control system for such a certificate management can in particular be managed fully automatically by the central registration service, ie without manual or semi-manual input by a user being necessary.
- the central registration service is preferably set up to manage the software inventory dynamically, ie for example the software inventory during operation to keep the system up to date. This makes it z. B. possible to provide the correct component-specific information in the software inventory even when a system component is replaced by a replacement component and to correctly check an, in particular initial, certification application for the replacement component.
- the central registration service is set up to update, in particular component-specific, information already stored in the software inventory on the basis of the transmitted component-specific information.
- the central registration service can be set up to change, supplement and / or expand information that has already been stored. It is conceivable, for example, that in the case of a changed project planning, according to which the system component has to communicate at least partially with other and / or additional components, the corresponding information stored in the software inventory is adapted. This enables a permanently reliable examination of certificate applications by the central registration service.
- the central registration service is set up to create a new data record on the basis of the transmitted component-specific information for a system component for which no, in particular component-specific, information is yet stored in the software inventory.
- the central registration service is preferably set up to include information contained in the certification application, for example a signature under the application and / or a device ID, which can be represented by a serial number, along with other information to take over component-specific information in the software inventory. This makes it possible to automatically fill an essentially empty software inventory, for example when the system is started up.
- the central registration service is set up to compare the transmitted component-specific information with, in particular component-specific, information stored in the software inventory and to generate a corresponding signal when an inconsistency is detected. For example, if a device is mistakenly integrated into several projects, i. H. For example, when used in different processes, the central registration service can recognize this on the basis of the certification applications received in relation to the multiple projects, in particular the component-specific information transmitted and stored in the software inventory, and output a corresponding message. In complex systems in particular, this can reduce the risk of incorrect configuration of a system component.
- the at least one local registration service is set up to subject the application for certification of the system component to a preliminary check on the basis of the component-specific information.
- the local registration service can already check the admissibility of the certification application within a system segment, e.g. B. according to system segment-specific criteria or criteria specific to the transmission protocol used.
- the at least one local registration service is preferably set up to forward the certification application together with the component-specific information to the central registration service as a function of a result of the test, in particular when the certification application is certified. In this way, applications that, for example, already turn out to be inadmissible within a system segment, can be filtered out early on and thus the data traffic within the control system can be reduced.
- the at least one local registration service is set up to obtain the component-specific information from an administration device which is set up to administer the system component.
- Management of a system component is understood to mean, in particular, a configuration and / or control of the system component.
- the management device can be, for example, what is known as an engineering station, which includes the configuration of a system segment or its system components and thus enables its autonomous operation and protection.
- the local registration service can preferably derive all the relevant component-specific information with regard to the check by the central registration service or also to the preliminary check itself. Access to information stored by the administrative device is particularly advantageous, since the administrative device is usually operated continuously and the information can thus be accessed at any time.
- control system has an administration device with an interface, the interface, also referred to as an adapter, being set up to determine component-specific information, in particular the system component making the request, and to provide it for the at least one local registration service.
- the interface can also be set up to process the information obtained for use by the local registration service, e.g. B. to be converted into a corresponding data format.
- the interface can be designed in particular as an application, ie as software, and for diagnosing the system segment, in particular the system component making the request and / or its system environment, be set up.
- An administrative device designed in this way makes it possible to compile the component-specific information if necessary, ie for example when requested by the local registration service.
- the component-specific information contains a project affiliation, which can be documented, for example, by a project-specific device certificate, a network-specific identification feature and / or a functional characteristic, in particular of the system component making the application.
- a project affiliation which can be documented, for example, by a project-specific device certificate, a network-specific identification feature and / or a functional characteristic, in particular of the system component making the application.
- Such features also known as meta information, can be used to classify the submitting component in the system context in particular. For example, their function and / or the interaction with other system components can be determined. On this basis, a full examination of the application can be carried out by a registration service.
- the compatibility and / or the authorization of the requesting component to communicate with another system component can be determined.
- a functional characteristic ie information regarding the functions or function clusters provided by the system component, it can be determined, for example, whether the applying component needs the certificate applied for for a specific function at all.
- Such functions can, for example, the monitoring and Control of processes running in the system and / or the diagnosis or maintenance of other system components.
- the central registration service is set up to check a certification of the local registration service on the basis of information stored in the software inventory.
- the central registration service can in particular be set up to check whether there is already an established trust relationship with the at least one local registration service.
- a signing certificate from the local registration service can be or will be stored in the software inventory, on the basis of which the central registration service can determine the permissibility of the forwarding of a certification application by the local registration service.
- a signature certificate possibly together with the associated trust chain, can be transmitted to the central registration service for storage in the software inventory, for example, when the system is initialized or at least the system segment assigned to the at least one local registration service or as part of a centrally initiated certificate rollout become.
- the central registration service can then, for example, check a signature of the local registration service in the transmitted certification application.
- the central registration service can in particular check whether the signature matches the certificate request, whether it was issued by the respective local registration service and / or whether it is trustworthy, i.e. H. whether it can be traced back to a central certification service on the basis of the chain of trust.
- the trust in certificates that have been checked by the central registration service and then issued, in particular by a central certification service can be increased further.
- the central registration service is preferably set up to process the software inventory as a function of a result of the examination of the certification of the local registration service to manage, in particular only to update information stored in the software inventory or to create a new data record if there is a trust relationship with the local registration service, ie the local registration service is or will be authenticated.
- the at least one local registration service is set up to authenticate the certification request before it is transmitted to the central registration service.
- the at least one local registration service can sign a certification application with a signing certificate, in particular a certification application that has been validated by it as part of a preliminary check.
- the central registration service is preferably set up to only validate such certification applications and, for example, to forward them to a central certification service if such a signing certificate is available. This can further increase trust in the communication security in the control system.
- the central registration service is set up to store information in the software inventory, in particular on the basis of the authenticated certification request, on the basis of which a certification of the at least one local registration service can be checked.
- the information can include, for example, a signature certificate from the local registration service and / or a certification path (trust chain) to the signature certificate with which the local registration service signed the certification request.
- trust chain a certification path
- a second aspect of the invention relates to a method for certificate management in a process plant, comprising the steps: (i) Transmission, by a local registration service, of a certification application for a plant component together with component-specific information contained in the certification application in particular to one central registration service; (ii) management of a central software inventory in which the component-specific information can be stored by the central registration service on the basis of the transmitted component-specific information; and (iii) checking the certification application by the central registration service on the basis of the component-specific information stored in the software inventory.
- the local registration service determines the component-specific information from the environment of the system component making the application.
- an environment can in particular be a, preferably self-sufficient, functional and secured system segment of the system, which z. B. is spatially and / or technically separated, for example by a firewall, from other system segments.
- the registration service preferably does not access the requesting component directly.
- the local registration service can request or query the component-specific information from an administrative device that is set up to manage, in particular to configure and / or control, the system component making the request, in particular via a corresponding interface.
- the component-specific information can be provided even if the component making the application is temporarily unavailable, for example shut down.
- FIG 1 shows an example of a control system 1 for certificate management in a process plant.
- the control system 1 has a central registration service 2 for checking a certification application submitted by one of the system components 3, a software inventory 4 for storing component-specific information, ie information relating to the respective system components 3 and, in the present example, two local registration services 5a, 5b for forwarding of the certification application from the respective system component 3 to the central registration service 2.
- the central registration service 2 is set up to check the certification application on the basis of the, in particular component-specific, information stored in the software inventory 4 and to forward it to a central certification service 6 as a function of a result of the check, in particular when the certification application is validated issues the corresponding certificate for system component 3.
- the central registration service 2 also set up to manage the software inventory 4 based on component-specific information that is transmitted to the central registration service 2 by one of the local registration services 5a, 5b together with the certification application. This enables the fully automatic and dynamic management of the software inventory 4.
- the central registration service 2 and the local registration services 5 are preferably connected to one another via a network, for example a terminal bus 7.
- System segments 1a, 1b of the system are preferably also connected to the terminal bus 7, with the system segments 1a, 1b being able to define so-called security cells, for example, through a spatial and / or data-technical separation, e.g.
- a local registration service 5a, 5b is preferably assigned to each system segment 1a, 1b.
- a management device 8 also referred to as an engineering station, can be provided per system segment 1a, 1b, which is connected to the system components 3 of the respective system segment 1a, 1b via a further network, for example a system bus 9 configured as Industrial Ethernet.
- the administration devices 8 preferably include the project planning of the respective plant segment 1a, 1b, ie they are set up for the configuration and / or control of the plant components 3 of the respective plant segment 1a, 1b.
- the management devices 8 and the system components 3, which are designed as user servers (operator station servers) in the present example, are preferably also connected to peripheral components 10, for example sensors, valves, actuators and / or the like, for controlling processes via the system bus 9.
- the respective system component 3 can submit a corresponding certification application which is transmitted via the terminal bus 7 to the responsible local registration service 5a, 5b.
- the local registration service 5a, 5b is preferably set up to then request the component-specific information on the system component 3 making the application from the respective administration device 8.
- the management device 8 is preferably set up to determine this information with the aid of a corresponding interface 11 and to make it available to the requesting local registration service 5a, 5b.
- the interface 11 can, for. B. be designed as an application and access the configuration of the plant segment 1a, 1b.
- the interface 11 can derive meta information from the project planning, for example relating to the functionality of individual system components 3 and / or their interaction with other system components 3, and, if necessary, prepare it for use by the local registration service 5a, 5b or the central registration service 2.
- the local registration services 5a, 5b can be set up to carry out a preliminary check of the respective certification application transmitted to them on the basis of the component-specific information provided by the administrative devices 8.
- the certification application can, for example, according to a standard protocol, e.g. B. the certificate management protocol also referred to as Certificate Management Protocol (CMP) according to the RFC 4210 standard, via the terminal bus 7 to the central registration service 2 are transmitted.
- CMP Certificate Management Protocol
- the responsible local registration service 5a, 5b is preferably set up to convert the certification application into the standard protocol if the certification application from the system component 3 is made using another Standards, e.g. B. the Open Platform Communications (OPC) Unified Architecture (UA) GDS, is transmitted.
- OPC Open Platform Communications
- the local registration services 5a, 5b are preferably set up to transmit the component-specific information together with the respective certification application, in particular as part of the respective certification application, to the central registration service 2.
- the application corresponds to an initial application for a certificate (bootstrapping)
- the component-specific information is entered in the software inventory 4.
- the component-specific information can thus form at least part of a new data record.
- the central registration service 2 preferably searches for an entry in the software inventory 4 for the corresponding system component 3 and, if necessary, compares the transmitted component-specific information with information stored in the software inventory 4.
- the central registration service 2 can then optionally update the information stored in the software inventory 4. This makes it possible to ensure that when certification applications are checked by the central registration service 2, current component-specific information is always available.
- FIG 2 shows an example of a software inventory 4 that is part of a control system of a process engineering plant.
- the software inventory 4 is designed as a database.
- the database contains nine data records, each with seven data fields, each data record being shown in one line and assigned to a system component.
- a local registration service 5a, 5b, 5c via which a certification application for the respective system component is transmitted to a central registration service be.
- Each local registration service 5a, 5b, 5c is certified on the basis of a signature certificate in the software inventory 4, whereby a trust relationship with the local registration service 5a, 5b, 5c is established.
- the certification is implemented here by an entry in the data fields 12a.
- Data fields 12b indicate the manufacturer of the respective system component, while a serial number of the respective system component is stored in data fields 12d. Furthermore, manufacturer certificates are stored in data fields 12e, user certificates in data fields 12f and operational certificates in data fields 12g. Of course, other component-specific information can also be stored in the data fields.
- the software inventory 4 can be dynamic, i. H. in the operation of the process plant, updated, in particular expanded, are.
- a certification application is received by the central registration service
- an already existing data record can be supplemented with further component-specific information.
- a new data record can also be added when a local registration service 5a, 5b, 5c transmits a signature certificate to the central registration service to establish a trust relationship, in particular when the system or at least one system segment is commissioned.
- the new data record only contains an entry in data field 12a. Later a certification application goes to a Plant components via this local registration service 5a, 5b, 5c at the central registration service, the data record can be expanded or updated as described.
- FIG 3 shows an example of a method 100 for certificate management in a process plant.
- a certification application is made by a system component, for example because the component wants to communicate with another system component in an encrypted manner and requires a corresponding certificate for this.
- the system component transmits the certification application to a local registration service, which is preferably assigned to a system segment, part of which is the system component and which is secured against other segments of the system, for example by spatial separation and / or in terms of data.
- the local registration service determines component-specific information, in particular meta information, which describes, for example, the function of the system components in the system segment and / or their interaction with other system components.
- component-specific information z. B. also deal with certificates, which are required for communication between system components.
- the local registration service When determining the information, the local registration service preferably does not access the relevant system component directly, but rather a system environment of the component.
- the local registration service can access an administrative device that is set up to configure and / or control all system components in the system segment.
- an administration device thus generally has the desired component-specific information or at least information from which the desired component-specific information can be derived.
- the local registration service checks the certification application on the basis of the component-specific information that has been determined. For example, the local registration service can check whether a communication intended by the system component, for which the certificate is requested, is actually provided within the scope of a project planning. To sign the validation of the certification application, the local registration service can sign the certification application, for example with the aid of a signing certificate which is issued by a central certification service for the local registration service.
- the certification application validated in this way is transmitted together with the component-specific information from the local registration service in a further method step S4 to a central registration service.
- the local registration service can enrich the certification application with the component-specific information.
- the central registration service uses this component-specific information, possibly after extraction from the transmitted certification application, in order to manage a software inventory.
- the central registration service can, for example, compare the transmitted component-specific information with information stored in the software inventory and update or supplement the software inventory as a function of a result of the comparison.
- the central registration service determines discrepancies or inconsistencies between the transmitted component-specific information and information stored in the software inventory, for example if, according to an entry in the software inventory for a further system component with which the requesting system component wants to communicate in accordance with the transmitted component-specific information, communication with the requesting system component is not allowed at all.
- the central registration service can provide a corresponding Signal, for example in the form of a message to a user of the system, generate and / or output.
- the central registration service checks the certification application on the basis of the information stored in the central software inventory. In particular, it can be checked whether there is a trust relationship with the transmitting local registration service, for example by authenticating the signature of the local registration service in the certification application on the basis of information stored in the software inventory. Depending on a result of the check, the central registration service can then validate the certification application, for example sign it, and forward it to the central certification service for issuing the requested certificate.
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- General Physics & Mathematics (AREA)
- Automation & Control Theory (AREA)
- Physics & Mathematics (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- General Engineering & Computer Science (AREA)
- Quality & Reliability (AREA)
- Manufacturing & Machinery (AREA)
- Computer Hardware Design (AREA)
- Computing Systems (AREA)
- Management, Administration, Business Operations System, And Electronic Commerce (AREA)
Priority Applications (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP19197796.6A EP3796107A1 (fr) | 2019-09-17 | 2019-09-17 | Système de guidage et procédé de gestion des certificats |
Applications Claiming Priority (1)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| EP19197796.6A EP3796107A1 (fr) | 2019-09-17 | 2019-09-17 | Système de guidage et procédé de gestion des certificats |
Publications (1)
| Publication Number | Publication Date |
|---|---|
| EP3796107A1 true EP3796107A1 (fr) | 2021-03-24 |
Family
ID=68051604
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| EP19197796.6A Withdrawn EP3796107A1 (fr) | 2019-09-17 | 2019-09-17 | Système de guidage et procédé de gestion des certificats |
Country Status (1)
| Country | Link |
|---|---|
| EP (1) | EP3796107A1 (fr) |
Cited By (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN116882636A (zh) * | 2023-09-05 | 2023-10-13 | 苏州浪潮智能科技有限公司 | 证书生命周期管理方法、装置、设备及存储介质 |
Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP1162781A2 (fr) * | 2000-06-09 | 2001-12-12 | TRW Inc. | Système et procédé de génération d'un certificat de signature dans une infrastructure à clé publique |
| EP3402152A1 (fr) * | 2017-05-08 | 2018-11-14 | Siemens Aktiengesellschaft | Gestion de certificat automatisée, en fonction de l'installation |
-
2019
- 2019-09-17 EP EP19197796.6A patent/EP3796107A1/fr not_active Withdrawn
Patent Citations (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| EP1162781A2 (fr) * | 2000-06-09 | 2001-12-12 | TRW Inc. | Système et procédé de génération d'un certificat de signature dans une infrastructure à clé publique |
| EP3402152A1 (fr) * | 2017-05-08 | 2018-11-14 | Siemens Aktiengesellschaft | Gestion de certificat automatisée, en fonction de l'installation |
Non-Patent Citations (1)
| Title |
|---|
| ANONYMOUS: "Prozessleitsystem - Wikipedia", 4 May 2017 (2017-05-04), XP055397767, Retrieved from the Internet <URL:https://de.wikipedia.org/w/index.php?title=Prozessleitsystem&oldid=165188304> [retrieved on 20170810] * |
Cited By (2)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| CN116882636A (zh) * | 2023-09-05 | 2023-10-13 | 苏州浪潮智能科技有限公司 | 证书生命周期管理方法、装置、设备及存储介质 |
| CN116882636B (zh) * | 2023-09-05 | 2024-01-16 | 苏州浪潮智能科技有限公司 | 证书生命周期管理方法、装置、设备及存储介质 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| EP3605253B1 (fr) | Initialisation automatisée des infrastructures à clé publique | |
| EP3985532A1 (fr) | Gestion des certificats pour installations techniques | |
| EP4147099A1 (fr) | Système et procédé pour vérifier des composants d'un système de contrôle industriel | |
| DE102014111361A1 (de) | Verfahren zum Betreiben einer Sicherheitssteuerung und Automatisierungsnetzwerk mit einer solchen Sicherheitssteuerung | |
| EP3993339B1 (fr) | Gestion des certificats dans une installation technique | |
| EP3762845B1 (fr) | Gestion des certificats relatif à un projet | |
| EP4578140B1 (fr) | Module technique sécurisé | |
| EP2304558A1 (fr) | Système et procédé de communication à distance entre un ordinateur central et une commande de machine | |
| EP3796107A1 (fr) | Système de guidage et procédé de gestion des certificats | |
| EP1496664A2 (fr) | Système, méthode et module de sécurité pour sécuriser l'accèss d'un utilisateur à au moins un composant d'automatisation d'un système d'automatisation | |
| DE102022101689A1 (de) | Verfahren zur Änderung eines Ist-Zugangsschlüssels in einem Feldgerät der Automatisierungstechnik | |
| DE102021127139A1 (de) | Systeme und verfahren zum sicheren einschränken der fahrbarkeit eines fahrzeugs durch beeinträchtigte benutzer | |
| WO2013041360A1 (fr) | Système et procédé pour fournir un code de programme de commande | |
| WO2020221523A1 (fr) | Procédé d'attribution de certificats, système de guidage, utilisation d'un tel système, installation technique, composants d'installation et utilisation d'un fournisseur d'identité | |
| EP3836489B1 (fr) | Attribution dynamique d'unités d'automatisation aux serveurs d'automatisation | |
| DE102020109294A1 (de) | Verfahren zum Betrieb eines Systems | |
| DE102016212755B3 (de) | Ethernet-Fahrzeugbordnetz mit geschützter Konfigurierbarkeit | |
| EP4254233A1 (fr) | Procédé et système de mise en oeuvre sécurisée d'applications de commande, hôte | |
| EP3339994A1 (fr) | Procédé de vérification d'une attribution de mandat, produit-programme informatique et dispositif | |
| EP4113928A1 (fr) | Système de commande pour une installation technique et procédé d'émission d'une demande de certificat pour un composant d'installation | |
| EP4432602A1 (fr) | Procédé de présentation d'un certificat et site d'enregistrement mis en uvre par ordinateur | |
| EP3944108A1 (fr) | Révocation de certificats dans une installation technique | |
| EP4181462A1 (fr) | Procédé de gestion des certificats pour installations hétérogènes, système informatique et produit-programme informatique | |
| DE102024210000A1 (de) | Inbetriebnahme eines Fortbewegungsmittels in der Produktion | |
| WO2026002646A1 (fr) | Procédé et dispositif de fourniture et de validation d'informations d'identité de dispositif sécurisées de manière cryptographique |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PUAI | Public reference made under article 153(3) epc to a published international application that has entered the european phase |
Free format text: ORIGINAL CODE: 0009012 |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION HAS BEEN PUBLISHED |
|
| AK | Designated contracting states |
Kind code of ref document: A1 Designated state(s): AL AT BE BG CH CY CZ DE DK EE ES FI FR GB GR HR HU IE IS IT LI LT LU LV MC MK MT NL NO PL PT RO RS SE SI SK SM TR |
|
| AX | Request for extension of the european patent |
Extension state: BA ME |
|
| STAA | Information on the status of an ep patent application or granted ep patent |
Free format text: STATUS: THE APPLICATION IS DEEMED TO BE WITHDRAWN |
|
| 18D | Application deemed to be withdrawn |
Effective date: 20210925 |